CVE-2018-0587
4.3
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
Affected (1)
Products: Ultimatemember: User Profile & Membership
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.4 |
References (6)
Source: vultures@jpcert.or.jp
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.